Description | This article describes how to decode UDP payload for reply packets between FGCP clusters sent through heartbeat link. |
Scope |
Synchronization between FGCP clusters and supporting UTM inspection on asymmetric traffic on L3 is used: |
Solution |
1) The return traffic passing through the heartbeat link between two clusters would be encapsulated as UDP traffic (24 bytes private header are added to UDP payload) 2) Make a packet capture on the link used as a heartbeat between two FGCP clusters. 3) Open the file using WireShark. 4) Select the packet to decode. 5) In Packet Bytes View, 'right-click' on it and select '…as a Hex Stream'.
6) Paste to 'Hex Packet Decoder' in below link and select decode https://hpd.gasmi.net/. 7) Remove 24 bytes private header from UDP payload. In below screenshot, it is the one enclosed in red.
8) Copy the one enclosed in orange and paste it to Hex Packet Decoder. Then select 'Decode'. For example, the below packet is for the SSH session from 172.18.16.2 to 172.18.32.3.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.